Muse is Meta's personal AI agent. You message it in the Muse app, in WhatsApp, on the web, or on your Mac. It works on its own cloud computer with a terminal and a browser, writes the tools a task needs, and checks with you before sensitive actions through a permission system Meta has documented in unusual depth. For one person's goals, it is excellent. Boring runs the work a company answers for: agents owned by a team, started where work arrives, and reviewed by the person assigned to decide, who can fix the proposed call before it runs. Use both. This page shows where the line sits.
Updated
If the work is yours, get Muse. It is free to start and reachable where you already message. It has its own Linux computer and browser, writes its own code and connectors, and Meta says it can now drive apps on your Mac. Meta has published its safety design in detail: a separate Sentinel that alone decides whether a connector action is allowed, denied, or put to you, approvals scoped to once, a task, a site, or always, read-only connectors, credentials the agent never sees, and a public bug bounty of up to $300,000. Boring answers a different question: who operates a workflow when the company has to answer for it. Its agents belong to a workspace rather than one person's Meta account. They start from webhooks, forms, app events, the workspace API, and schedules as well as from people. By default, each connected action waits for an assigned reviewer who can approve it, modify the exact call, or reject it, with a due date. Give Muse your to-do list. Give Boring your team's runbook.
| Capability | Boring AI | Muse from Meta |
|---|---|---|
| // shape of the product | ||
| What it is | A console where a team builds, operates, and reviews automation agents. | In Meta's words, "a personal AI agent" that lives on Muse Secure VM, its own dedicated cloud computer, powered by Meta's Muse Spark model. |
| Who owns and directs it | A workspace: roles, private or workspace visibility, live co-editing, and versioned definitions where every change is a diff you can roll back. | One person, signed in with a Meta account: "You and your Muse share your own dedicated computer in the cloud." Muse for Small Business adds skills and connectors inside Muse; a team workspace, seats, or roles are not specified in Meta's public docs. |
| Where you talk to it | The console and the workspace assistant (⌘J), a native mobile companion for approvals (store release pending), and email or Slack notifications. Not a chat-app product. | Its strength: the Muse app, WhatsApp, the web, and the Mac desktop app today, in one long conversation with side chats. Meta announced a voice mode at Connect 2026. |
| A computer of its own | No computer use or signed-in browsing. Agents act through connected tools and can load public web pages. | Its own Linux VM with a file system, terminal, and full browser; it writes its own code, tools, and custom connectors. Meta says computer use in Muse for Mac is now available; some coverage still calls it upcoming. |
| // judgment and control | ||
| What waits for a person | New agents start with every connected action waiting for approval. Owners loosen it to writes only or auto-approve eligible actions they trust, such as reads; an action Boring can't classify counts as a write. | Sentinel, a separate agent Muse can't override, decides whether each connector action is allowed, denied, or put to you. An "Always ask" setting asks before any action, and sensitive writes from platform connectors can never be set to Always allow. |
| Who decides, and what they can change | An assigned reviewer in a shared Tasks inbox can approve, modify the proposed call, or reject it, and the agent's owner or an admin can reassign it. Reviews can carry due dates, reminders, and a configured overdue outcome. | The owner, in an approval dialog in the Muse client, with options such as Allow once, Allow for this task, Allow for this site, Always allow, or Deny. Editing the proposed action first, or routing it to another reviewer, is not specified in Meta's public docs. |
| Hard limits on actions | Exact-action grants are enforced in code: an agent without the send action cannot send, whatever its instructions say. | Also enforced outside the model: in Meta's words, "deterministic boundaries apply even if Muse is persuaded to behave badly". Read and write access are separated where the service supports it, more finely than OAuth scopes, and many connectors can be set to retrieve data only. |
| Record of the work | One shared trace per run: reasoning, tool calls, approvals, and cost. Tool payloads are kept 90 days; the outcome, output, and step list stay. Run summaries export as CSV or JSON. | For its owner: an Activity log of "actions your Muse has taken and permissions you've given it", plus VM files and memory you can inspect and download. Team access to that record is not specified in Meta's public docs. |
| // starting, recovering, model, and price | ||
| How work starts | Schedules, webhooks, inbound email, public forms, SaaS app events, the Chrome extension, the workspace API, MCP clients, and other agents. | Conversation, goals it keeps advancing "on a schedule and in response to relevant events", connectors that push updates such as calendar changes, and its own ideas. A webhook, form, or API that starts work is not specified in Meta's public docs. |
| When something fails | Resume eligible failed runs from the last completed step; in a numbered step plan, when an action's outcome is uncertain, Boring blocks automatic repetition instead of guessing. Recognized provider failures are labeled, with the provider's reference ID. | VM data is backed up continuously, and you can ask Muse to stop or undo some actions; others, like sending an email, "cannot be reversed". Retry or resume semantics are not specified in Meta's public docs. |
| The model | Claude Sonnet 5.5 by default, managed GPT, Gemini, and Grok with no key, or your own Anthropic, OpenAI, Google, OpenRouter, or compatible-endpoint key. | Muse Spark, Meta's own model (version 1.3, per Meta's security post). A model picker or bring-your-own-key is not specified in Meta's public docs. |
| Training on your work | We never train foundation models on your content. | Uses sanitized interaction trajectories for training by default, with an opt-out switch in Muse settings. Conversations and VM data aren't shared with Meta's ad systems. |
| Price and access | Early access, on design-partner terms, with white glove if you want the agents built and operated with you. | Free with a usage limit, Power at $20 a month, or Maximum at $100 a month, as of October 2026. Available to adults in the United States and Canada; subscriptions are in limited testing. |
Details about Muse come from Meta's own newsroom and blog posts, Help Center, research blog, and muse.ai pages, checked 3 October 2026. Where Meta's sources and press coverage disagree, as they do on computer use in Muse for Mac, we say so. Where Meta's public docs don't specify something, we say that rather than call it missing. Muse is changing quickly; if anything here is out of date, tell us and we'll fix it.
Meta calls Muse "a personal AI agent", and everything about it is built around one person. "You and your Muse share your own dedicated computer in the cloud," Meta's security post says. You sign in with your Meta account and give it goals; it keeps working on them, remembers what matters to you, and messages you when something is meaningfully new. Muse for Small Business keeps that shape. Meta describes it as "a collection of new skills and connectors inside Muse" that links the owner's tools, from Shopify and Intuit QuickBooks to Facebook Pages and Meta ad accounts. For one owner running one business, that is a sensible design.
A company workflow has a different shape. The refund queue, vendor onboarding, and the Monday customer report each have several people who edit them, review what they did, and answer for the result. Boring puts agents in a workspace, with roles, private or workspace visibility, live co-editing, and one shared record per run, and every change to a definition is a versioned diff you can roll back. Meta's public docs don't specify team workspaces, seats, or roles for Muse. Meta has announced a Meta Enterprise Platform that will bring "the Muse agent" to businesses, without product details so far; when it publishes them, we'll update this page.
Muse's controls are deterministic, and Meta documents them in unusual depth. A separate Sentinel agent, which Muse can't override, is the sole permission authority for connector actions and outbound network traffic, and decides whether each action is allowed, denied, or put to you. Approvals are, in Meta's words, "strict capabilities, not conversational suggestions": once, for a task, for a site, for a set time, or always. Connectors can be limited to reading, sensitive writes from platform connectors can never be set to Always allow, and real credentials are inserted at the network boundary so the agent never sees them. Meta backs the design with a public bug bounty of up to $300,000.
The difference is who gets asked and what they can do. Muse puts each request to its owner, as an approval dialog in the Muse client. Boring routes the decision. New agents start with every connected action waiting for approval, and each request leads with the exact tool call and its scrubbed arguments. It goes to an assigned reviewer with a due date, reminders, and a configured overdue outcome of reject or skip, and that reviewer can approve, reject, reassign, or modify the exact arguments before the call runs. Meta's public docs describe accept/reject and allow/deny choices; editing a proposed action before approving it, or routing it to someone other than the owner, is not specified.
Muse starts from conversation, keeps working on your goals "on a schedule and in response to relevant events", hears from connectors that push updates, such as a calendar change, and brings you ideas of its own. That covers a great deal of personal work. A company's work also arrives as a webhook from another system, a form a customer submits, an event in a SaaS app, or a call to an API. Boring starts runs from all of those, plus schedules, inbound email, the Chrome extension, MCP clients, and other agents. Meta's public docs don't specify a webhook, form, or API that starts work in a user's Muse; Meta Enterprise Platform lists a Muse API among what it will bring to businesses and developers, without details so far.
When a Boring run breaks, its saved plan and progress stay, and eligible failed runs resume from the last completed step. In a numbered step plan, when a write's outcome is uncertain, Boring blocks automatic repetition instead of guessing. For eligible runs, provider throttling and outages are waited out within a bounded window; if the provider stays down, the run ends with its saved progress and a clear reason. Recognized provider failures are labeled billing, rate limit, or context size, with the provider's reference ID, and a deliberate safety stop is flagged as one. Muse backs up VM data continuously so you can restore it, and you can ask it to stop or undo some actions; Meta notes that others, like sending an email, cannot be reversed. Retry and resume semantics for its background work are not specified in Meta's public docs.
Muse runs on Muse Spark, Meta's own model, and Meta's public docs don't specify a model picker or a way to bring your own key. Meta is direct about its data terms: Muse uses sanitized interaction trajectories for training by default, with an opt-out switch in Muse settings, and it doesn't share conversations or VM data with Meta's ad systems. For a personal agent, those are reasonable terms, clearly stated.
A team choosing where its operations run usually wants to set those terms itself. Boring runs new agents on Claude Sonnet 5.5 by default, offers managed GPT, Gemini, and Grok with no key, and accepts your own Anthropic, OpenAI, Google, OpenRouter, or compatible-endpoint key. Pin a different model for one agent or the whole workspace when a job calls for it. And we never train foundation models on your content.
Sources:Introducing MuseMuse for Small BusinessMuse for Small Business pageHow We Designed MuseHow We Built Safety Into MuseConnect 2026 announcementsGuidance and approvalHow Muse works with ConnectorsMuse subscriptionsConnector Platform guidelinesMeta Enterprise Platform
Yes, and that's the split we'd suggest. Give Muse your to-do list: your inbox, your errands, your goals, the decisions only you make. Run what the company answers for through Boring: the queues, hand-offs, and recurring jobs that several people own, that start from other systems, and that need an assigned reviewer and a shared record. The two don't need to be connected to be useful side by side.
For your own work, it often is. Muse's Sentinel decides whether each connector action is allowed, denied, or put to you, approvals are scoped to once, a task, a site, or always, and connectors can be read-only. Boring doesn't claim stronger enforcement than that. The difference is who gets asked and what they can do. In Boring, the request goes to an assigned reviewer with a due date and reminders, leads with the exact tool call, and can be approved, rejected, reassigned, or modified before it runs, and the decision stays in a run record the team can review.
Meta describes it as "a collection of new skills and connectors inside Muse": it links a business owner's tools, such as Shopify, Intuit QuickBooks, Slack, and Stripe, plus Facebook, Instagram, and Meta ad accounts, so that, in Meta's words, Muse "will start out already understanding your business". A shared workspace, seats, roles, or routing approvals to someone other than the owner are not specified in Meta's public docs. Meta has also announced a Meta Enterprise Platform that will bring the Muse agent to businesses; product details weren't published when we checked, and we'll update this page when they are.
Muse runs on Muse Spark, Meta's own model; Meta's security post names version 1.3, and its public docs don't specify a model picker or bring-your-own-key. Boring runs new agents on Claude Sonnet 5.5 by default, offers managed GPT, Gemini, and Grok with no key, and accepts your own Anthropic, OpenAI, Google, OpenRouter, or compatible-endpoint key. Pin a different model for one agent or the whole workspace.
No, and if conversation is the job, Muse is the better tool. Boring is not a chat-app product. You work in the console, where the workspace assistant (⌘J) finds which agents need attention, what's waiting on a person, and where spend went, then prepares fixes, runs, or approvals as cards that change nothing until you confirm. Notifications go out by email and Slack, and a native mobile companion for approvals is built, with its store release pending.
We've tried to make it so. Every fact about Muse comes from Meta's own pages, checked on 3 October 2026, and we quote Meta where the wording matters. The one place we mention press coverage is where it disagrees with Meta, on computer use in Muse for Mac, and the page says so. We left out figures we could only find in press coverage and features Meta has announced but we couldn't confirm as live, and where Meta's docs don't specify something we say exactly that rather than call it missing. The page also says plainly where Muse wins: reach, a computer of its own, published security engineering, and a way to start free. If we got something wrong, tell us and we'll fix it.
Request access and describe it in a sentence — or ask about white glove and our team will build and run it with you.